Skip to content

Checkmarx high severity risk for cy.api's yauzl dep #224

@jprealini

Description

@jprealini

We are running Cypress 12.8 (planning to upgrade sooner than later) and using this plugin... since a couple of weeks ago our Checkmarx validation started to yell due to a high severity security risk for the "yauzl" package (among others) which is a dependency of cy-api.

What would be the approach to try to solve this? (For cy-api or any other packages.. we are getting high severity risk for other dependencies, most of them are Cypress' deps, but also some of other packages). Try asking Cypress and every npm package developer that has this issues to try to upgrade their dependencies?

I guess that just bypassing or ignoring these kind of warnings in Checkmarx is not an option.

cypress / yauzl @ 2.10.0
cypress / debug @ 3.2.7
cypress-grep / debug @ 4.3.1
cypress / debug @ 4.3.4
cypress / inflight @ 1.0.6

image

Thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions